Organization Policy API, REST: AuthenticationPolicyRule.List
Lists authentication policy rules in the specified organization.
HTTP request
GET https://organization-manager.api.cloud.yandex.net/organization-manager/v1/policy/authenticationPolicyRules
Query parameters
|
Field |
Description |
|
organizationId |
string Required field. ID of the organization to list authentication policy rules for. The maximum string length in characters is 50. |
|
pageSize |
string (int64) Maximum number of authentication policy rules to return. Acceptable values are 0 to 1000, inclusive. |
|
pageToken |
string Page token returned in ListRulesResponse.nextPageToken by a previous request. The maximum string length in characters is 2000. |
|
filter |
string Filter expression applied to the returned rules. The maximum string length in characters is 1000. |
Response
HTTP Code: 200 - OK
{
"authPolicyRules": [
{
"id": "string",
"name": "string",
"description": "string",
"organizationId": "string",
"effect": "string",
"obligations": [
{
// Includes only one of the fields `stepUpRequired`, `skipMfa`, `reauthenticationRequired`
"stepUpRequired": {
"acrId": "string",
"ttl": "string"
},
"skipMfa": {
"requireOnce": "boolean"
},
"reauthenticationRequired": {
"ttl": "string"
}
// end of the list of possible fields
}
],
"createdAt": "string",
"updatedAt": "string",
"subjectsInclude": [
"string"
],
"subjectsExclude": [
"string"
],
"networksInclude": [
"string"
],
"networksExclude": [
"string"
],
"applicationsExclude": [
"string"
],
"applicationsInclude": [
"string"
],
"status": "string",
"labels": "object"
}
],
"nextPageToken": "string"
}
|
Field |
Description |
|
authPolicyRules[] |
Authentication policy rules matching the request. |
|
nextPageToken |
string Token to retrieve the next page of results. |
AuthenticationPolicyRule
|
Field |
Description |
|
id |
string ID of the authentication policy rule. |
|
name |
string Name of the authentication policy rule. |
|
description |
string Description of an authentication policy rule. 0-256 characters long. |
|
organizationId |
string ID of the organization that the authentication policy rule belongs to. |
|
effect |
enum (Effect) Effect to apply when the rule matches.
|
|
obligations[] |
Obligations to satisfy when the effect is ALLOW_WITH_OBLIGATIONS. |
|
createdAt |
string (date-time) Creation timestamp. String in RFC3339 To work with values in this field, use the APIs described in the |
|
updatedAt |
string (date-time) Modification timestamp. String in RFC3339 To work with values in this field, use the APIs described in the |
|
subjectsInclude[] |
string List of IDs of subjects affected by the authentication policy rule. |
|
subjectsExclude[] |
string List of IDs of subjects not affected by the authentication policy rule. |
|
networksInclude[] |
string Source IP ranges in CIDR notation that the authentication policy rule applies to. |
|
networksExclude[] |
string Source IP ranges in CIDR notation excluded from the authentication policy rule. |
|
applicationsExclude[] |
string List of IDs of applications not affected by the authentication policy rule. |
|
applicationsInclude[] |
string List of IDs of applications affected by the authentication policy rule. |
|
status |
enum (Status) Status of the authentication policy rule.
|
|
labels |
object (map<string, string>) Labels of the authentication policy rule. |
Obligation
|
Field |
Description |
|
stepUpRequired |
Require step-up authentication. Includes only one of the fields |
|
skipMfa |
Allow skipping the organization's current MFA requirements. Includes only one of the fields |
|
reauthenticationRequired |
Require full authentication again. Includes only one of the fields |
StepUpRequired
|
Field |
Description |
|
acrId |
string Required field. ACR ID required to satisfy this obligation. The maximum string length in characters is 50. |
|
ttl |
string (duration) Required field. Maximum age of a factor verification that can satisfy this obligation. |
SkipMfa
|
Field |
Description |
|
requireOnce |
boolean If true, the organization's current MFA requirements must have been satisfied at least once |
ReauthenticationRequired
|
Field |
Description |
|
ttl |
string (duration) Required field. Maximum age of an authentication that can satisfy this obligation. |